Back to blogWhen CMMC Phase 2 is paused, what manufacturers should still do on NIST 800-171 and SPRS
    By Jeff Dennis, Founder & CEOOctober 8, 2026

    When CMMC Phase 2 is paused, what manufacturers should still do on NIST 800-171 and SPRS

    What the Phase 2 pause actually changed

    In July 2026, the Department of Defense suspended CMMC Phase 2. The big change is about who assesses you, not whether you still have to protect CUI.

    During the suspension, requiring activities may generally include only CMMC Level 1 (Self) or Level 2 (Self) in new procurements. Third-party Level 2 (C3PAO) and Level 3 (DIBCAC) designations for new contract requirements are on hold. The November 2026 Phase 2 transition that many teams were planning around is suspended pending reform review.

    What did not pause:

    • DFARS 252.204-7012 safeguarding and 72-hour cyber incident reporting
    • Implementation of NIST SP 800-171 Rev. 2 for covered defense information
    • SPRS assessment scores and related self-assessment expectations where your contracts and clauses require them
    • Annual affirmations tied to Level 1 / Level 2 self-assessment when your award requires them
    • Basic safeguarding of Federal Contract Information under FAR 52.204-21

    Official guidance is clear: during the suspension the Department will still enforce baseline compliance with NIST SP 800-171 Rev. 2 through self-assessment and select government-led assessments. If you want the primary source, start with the DoD CIO Implementing Suspension of CMMC Phase II memorandum.

    Why manufacturers should not treat this as a free pass

    Most manufacturers in the DoD supply chain do not live on certification calendars alone. You live on prime flow-downs, RFQ cybersecurity questionnaires, and whether your SPRS number looks real.

    A pause on third-party CMMC designations does not erase:

    • Contract language that already requires 7012 / 800-171
    • A prime that still demands evidence, an SSP, or a minimum SPRS score before you stay on the bid list
    • False Claims Act risk if you affirm a posture you cannot defend

    If your drawings, specs, or program data are CUI (or you process Covered Defense Information), the operational work remains the same: scope it, protect it, document it, and score it honestly.

    Keep NIST 800-171 moving: a shop-floor checklist

    Treat the pause as time to close real gaps, not as a reason to freeze the program. Use this sequence.

    1. Reconfirm CUI scope (one page is enough to start)

    Write down where CUI enters, where it sits, and where it leaves:

    • Email and file shares
    • ERP / PLM / MES
    • Engineering workstations and CAD vaults
    • Shop-floor systems that open drawings or travelers
    • Vendor portals and remote access paths

    If a CNC controller or tablet opens CUI drawings, it is in scope. "OT is separate" is not a control.

    2. Refresh the asset inventory against that boundary

    You need an authoritative list of in-scope endpoints, servers, SaaS, and network gear. Stale inventories produce stale SPRS scores.

    3. Score all 110 controls against reality

    Use NIST SP 800-171A style objectives. Mark each control YES / PARTIAL / NO based on what exists today, not what is "in progress" without evidence.

    Then calculate (or recalculate) your SPRS score with the DoD methodology. Do not invent points you cannot show an assessor, a prime, or a government reviewer.

    4. Put the gaps in a living POA&M

    Every open item needs:

    • A named owner
    • A target date
    • A status someone reviews weekly

    An undated POA&M reads as "we will never fix this."

    5. Lock an SSP that matches the plant you actually run

    Your System Security Plan should describe the current environment, the CUI boundary, residual risk, and how each in-scope control is implemented. If the document and the shop disagree, the shop wins in an assessment. Fix the document or fix the control.

    For a manufacturer-oriented walkthrough of this sequence, see The Manufacturer's Guide to NIST 800-171.

    SPRS: what "good" looks like while Phase 2 is paused

    SPRS is still how many primes and programs size you up. A few operator rules:

    • Accuracy beats optimism. An inflated score creates False Claims Act exposure. An honest lower score with a dated POA&M is defensible. A fiction is not.
    • Keep the submission current. Know when your last assessment was posted, what score you claimed, and which systems it covered.
    • Align score, SSP, and evidence. If SPRS says MFA is implemented, your identity reports and admin accounts should prove it.
    • Watch prime thresholds. Many primes want a positive score. Some want closer to 110. Confirm what *your* primes require in writing, not what a LinkedIn thread claims.

    During the pause, self-assessment quality matters more, not less. You may not face a C3PAO on day one of every new award, but you can still face government-led review, prime due diligence, and contract clauses that expect 7012 performance.

    High-leverage controls manufacturers usually underfund

    If bandwidth is limited, prioritize work that closes multiple weighted gaps and reduces real incident risk:

    • MFA on remote access, email, and admin accounts
    • Unique admin IDs (shared "admin" is a finding waiting to happen)
    • FIPS-validated encryption for endpoints and removable media where required
    • Centralized logging with retention and actual weekly review
    • Incident response that includes 72-hour DoD reporting paths and a recent tabletop
    • Vendor flow-down for subcontractors who touch your CUI

    These are not "CMMC theater." They are the controls that fail quietly on the plant floor and then show up in RFQs.

    What to ask your primes this week

    Send a short note (or put it on the next QBRs):

    1. Which of our current POs or upcoming bids still require DFARS 252.204-7012 / NIST 800-171 evidence?
    2. Do you still require a minimum SPRS score, and what is it?
    3. What artifacts do you want on file: SSP, POA&M, SPRS screenshot, policies, or a third-party report?
    4. If Phase 2 resumes, what lead time do you expect from us?

    Do not assume every prime paused their supplier bar because DoD paused Phase 2 designations.

    A 30-day plan if you froze the program after the announcement

    Week 1: CUI boundary sketch, asset list refresh, pull your last SPRS submission.

    Week 2: Control-by-control gap pass on the 110. Recalculate score. Draft or update POA&M owners and dates.

    Week 3: Close quick wins (MFA coverage, shared admin cleanup, logging retention, removable media encryption).

    Week 4: SSP revisions, IR tabletop date on the calendar, written confirmation of prime expectations.

    If you want a structured self-score first, use the free compliance checklist. For the broader CMMC context during the suspension, see our CMMC compliance overview.

    Bottom line

    CMMC Phase 2 timing is uncertain. Your obligation to safeguard Covered Defense Information is not. Manufacturers that keep NIST 800-171 implementation, honest SPRS scoring, and prime-ready evidence moving will be ready whether Phase 2 stays paused, resumes, or reforms.

    If you want a senior engineer to walk your current score and the gaps primes notice first, book a free 45-minute Compliance Gap Audit. You keep the written snapshot either way.

    Keep exploring

    More from the TRNSFRM team.

    All Blog Posts

    Browse every cybersecurity and IT article.

    Case Studies

    Real CMMC, NIST, and FTC outcomes.

    Free Compliance Checklist

    Score yourself across 47 controls in 10 minutes.

    Compliance Frameworks

    CMMC, NIST 800-171, ISO 27001, HIPAA, FTC, ITAR.

    Cybersecurity Operations

    24/7 MDR, SOC, and threat response.

    IT Resilience Framework

    Assess, Remediate, Operate, Improve. A continuous lifecycle.

    ITAR Compliance Checklist

    Work through ITAR readiness control by control.

    MSP Partner Program

    White-label security and compliance for MSPs.

    Choosing a Cybersecurity Firm

    2026 buying guide and provider directory.

    More industries we secure

    Regulated-industry programs built by TRNSFRM.

    Aerospace & Space

    AS9100, CMMC, ITAR programs for aerospace suppliers.

    Ambulatory Surgery Centers

    HIPAA-grade IT for ASCs and outpatient surgery.

    Automotive Suppliers

    TISAX, CMMC, and OEM cyber flow-downs.

    Behavioral Health

    HIPAA + 42 CFR Part 2 for behavioral health providers.

    Defense & DoD Suppliers

    CMMC 2.0 & NIST 800-171 for the defense industrial base.

    Dental Practices

    Real HIPAA compliance for dental groups and DSOs.

    Featured cybersecurity insights

    Deeper reads from the TRNSFRM team.

    Building an Incident Response Plan You'll Actually Use

    A pragmatic IR playbook, not a shelf binder.

    Cloud Misconfigurations: The #1 Cause of Data Breaches

    Where teams get cloud wrong — and how to fix it.

    CMMC 2.0: What Defense Contractors Must Do Now

    The DIB compliance clock is ticking.

    Deepfake Fraud in the Boardroom: The New CEO Scam

    Why voice and video attacks now target execs.

    MFA Bypass Techniques and How to Stop Them

    Attackers are getting past MFA — here's how.

    Quantum Computing and the Cryptography Apocalypse

    Start planning your post-quantum crypto migration.

    Call Now